Web Hosting Talk







View Full Version : Lets Beat The Vietnamese PayPal Hackers


dolay
01-22-2005, 08:53 PM
It is enough! Those Vietnamese PayPal hackers are easily hacking PayPal accounts and they usually made fraudelent purchase from Web Hosting Services.
We are one of the abused service about it and i heard most of the web hosting services living this problem already. PayPal.com seems to be so weak to fix their security holes so i decide to start a campaign here to deciphered them.
Please apply to this campaign with your reports
At this time this is only way to kick them out of internet business. Maybe some legals will see this thread and going to take care of that matter by understanding how they become a phantom menace! I am not sure about that but as i heard those Vietnamese hackers are specially educated by the North Korea from childhood and they practice their lessons like those actions.

Here are the below that i found fraudalent spurchase details that i found from our sales db. that are done from same origins. Please post your owns too.

1- DATE AND TIME : 2004-08-10 08:08:55
ORDER NUMBER : 200408100844Q867014498
PAYPAL ORDER NUM: S-9JW56943YS7316048
IP RECORD : 203.162.3.145

NAME AND SURNAME : Richard Miyata
E-MAIL ADDRESS : mrphoung_1984@yahoo.com
DOMAIN NAME : www.mrphuong.com

CONTROL PANEL : Ensim Pro
WEBSPACE : 5000 MB
BANDWITH : 500000 MB
WEBSPACE PRICE PER MB : 0.00075 USD
BANDWITH PRICE PER MB : 0.0002 USD

TOTAL : 871.5 USD
PAYMENT : Yearly


2- DATE AND TIME : 2004-08-15 18:08:40
ORDER NUMBER : 200408151803Q391268818
PAYPAL ORDER NUM. :S-1GJ80356DE201672C
IP RECORD : 153.110.132.10
YOUR COUNTRY : USA

NAME AND SURNAME : SUNG YUP KIM
E-MAIL ADDRESS : mrphuong_1984@yahoo.com
DOMAIN NAME : www.mrphuong.com

CONTROL PANEL : Ensim Pro
WEBSPACE : 50000 Mb
BANDWIDTH : 100000 Mb
WEBSPACE PRICE PER Mb : 0.0004 USD
BANDWIDTH PRICE PER Mb : 0.00025 USD

TOTAL : 378 USD
PAYMENT : Yearly


3- DATE AND TIME : 2005-01-03 19:01:02
ORDER NUMBER : 200501031905Q1926498579
PAYPAL ORDER NUM. :S-29L94515GE301124J
ORDER TYPE : New Order
IP RECORD : 167.206.61.66
YOUR COUNTRY : Viet Nam

NAME AND SURNAME : Le Thanh Tung
E-MAIL ADDRESS : clmkal@gmail.com
DOMAIN NAME : vnhitech.org

CONTROL PANEL : Ensim Pro
WEBSPACE : 20000 Mb
BANDWIDTH : 200000 Mb
WEBSPACE PRICE PER Mb : 0.0004 USD
BANDWIDTH PRICE PER Mb : 0.0002 USD
10 DEDICATED IPs: 180 USD (Yearly)

TOTAL : 583.2 USD
PAYMENT : Yearly
PAYMENT METHOD : PayPal

4- DATE AND TIME : 2005-01-22 16:01:06
ORDER NUMBER : 200501221643Q524517542
PAYPAL ORDER NUM. :S-1P753184BN2447008
ORDER TYPE : New Order
IP RECORD : 24.9.102.61
YOUR COUNTRY : USA
REFERRER : Google

NAME AND SURNAME : David Spears
E-MAIL ADDRESS : xedapvn@nhakho.info
DOMAIN NAME : thaonguyenloves.org

CONTROL PANEL : cPanel
WEBSPACE : 10000 Mb
BANDWIDTH : 100000 Mb
WEBSPACE PRICE PER Mb : 0.0005 USD
BANDWIDTH PRICE PER Mb : 0.00025 USD

TOTAL : 252 USD
PAYMENT : Yearly
PAYMENT METHOD : PayPal


Note1. Those are the signups that have a payment too otherwise sometimes we get 10-15 signups a day that have not a payments from same origins.

Important Note2. As you seen the domain or e-mail addresses have letters like that "thaonguyen" , "vnhitech" , "mrphuong" ... which are easily sensed to be a Vietnamese words!

Overman
01-22-2005, 09:13 PM
Great job. I will support this campaign.

macdonaldp
01-22-2005, 10:13 PM
Originally posted by dolay
We are one of the abused service about it and i heard most of the web hosting services living this problem already. PayPal.com seems to be so weak to fix their security holes...
Question though. Is it really paypal's fault, or is it really the users fault.
1. Not choosing secure enough passwords
2. Clicking emails, not sent from paypal, that tell them to "confirm" their paypal details?

jt2377
01-22-2005, 10:39 PM
Originally posted by directssl
Question though. Is it really paypal's fault, or is it really the users fault.
1. Not choosing secure enough passwords
2. Clicking emails, not sent from paypal, that tell them to "confirm" their paypal details?

true. paypal and ebay try to educate their users about their account secrity but there is only so much you can do if your users still didn't do what you ask them to do.

dolay
01-23-2005, 01:04 AM
Originally posted by jt2377
true. paypal and ebay try to educate their users about their account secrity but there is only so much you can do if your users still didn't do what you ask them to do.

Its not that easy! It is not only a PayPal username+pass hijacking! It is exactly not the faults or excuse of PayPal account owners.

Ie. mail: mrphuong_1984@yahoo.com . This is also the PayPal accounts e-mail. Those hackers are creating their own paypal accounts and they are doing it by hacking PayPal!

As you seen Their hackings are absolutely not limited with only those ways mentioned by you!

I offer you to read my thread well and i would be so glad if you can report their fraud signup details (with their IPs if possible). Otherwise if you claim those are only become from the faults of PayPal users then those hackers will continue to make fraud signups forever and we and most of the known web hosting services that work with PayPal will suffer from those frauds forever. Aiming of this thread is for taking the attention of real responsibles

Amish_Geek
01-23-2005, 01:18 PM
Originally posted by dolay
Its not that easy! It is not only a PayPal username+pass hijacking! It is exactly not the faults or excuse of PayPal account owners.

Ie. mail: mrphuong_1984@yahoo.com . This is also the PayPal accounts e-mail. Those hackers are creating their own paypal accounts and they are doing it by hacking PayPal!

As you seen Their hackings are absolutely not limited with only those ways mentioned by you!

I offer you to read my thread well and i would be so glad if you can report their fraud signup details (with their IPs if possible). Otherwise if you claim those are only become from the faults of PayPal users then those hackers will continue to make fraud signups forever and we and most of the known web hosting services that work with PayPal will suffer from those frauds forever. Aiming of this thread is for taking the attention of real responsibles

Actually, once a phisher has someones login/password for their paypal account, the phisher can add their own email address to the paypal account. It is not really hacking, but a phishing scam. And the poor paypal users are too stupid to know any better.

dolay
01-23-2005, 09:06 PM
IT SEEMS THEY SEEN THIS WHT AND THATS WHY WE HAVE RECIEVED MORE 4 FRAUDELENT PAYPAL PAYMENT WITHIN THE LAST 24HRS

5- DATE AND TIME : 2005-01-23 11:01:29
ORDER NUMBER : 200501231139Q1644757195
PAYPAL ORDER NUM. :S-7KA40420MT378115G
ORDER TYPE : New Order
IP RECORD : 165.234.136.183
YOUR COUNTRY : USA
REFERRER : Google

NAME AND SURNAME : Jennifer Dorward
E-MAIL ADDRESS : admin@timyeu.biz
DOMAIN NAME : huynhdevn.org

CONTROL PANEL : cPanel
WEBSPACE : 10000 Mb
BANDWIDTH : 100000 Mb
WEBSPACE PRICE PER Mb : 0.0005 USD
BANDWIDTH PRICE PER Mb : 0.00025 USD

TOTAL : 252 USD
PAYMENT : Yearly
PAYMENT METHOD : PayPal


6- DATE AND TIME : 2005-01-23 11:01:23
ORDER NUMBER : 200501231156Q479461821
PAYPAL ORDER NUM. :S-7E170799FY3043620
ORDER TYPE : New Order
IP RECORD : 165.234.136.183
YOUR COUNTRY : USA
REFERRER : Google

NAME AND SURNAME : Tim Powell
E-MAIL ADDRESS : langkhach_muathu@yahoo.com
DOMAIN NAME : web1vn.net

CONTROL PANEL : cPanel
WEBSPACE : 10000 Mb
BANDWIDTH : 100000 Mb
WEBSPACE PRICE PER Mb : 0.0005 USD
BANDWIDTH PRICE PER Mb : 0.00025 USD

TOTAL : 252 USD
PAYMENT : Yearly
PAYMENT METHOD : PayPal


7- ORDER NO : 200501231529-2IPY-491
PAYPAL ORDER NUM. : S-68V98331B2050684U
ORDER IP : 68.6.164.192

NAME : xedapvn
E-MAIL : xedapvn@nhakho.info
DOMAIN NAME : thaonguyenloves.org
NUMBER OF IP: 2
NAME SERVERS:
ns1.thaonguyenloves.org ns2.thaonguyenloves.org

PAYMENT TYPE: Yearly
TOTAL : 36.00 USD

8- DATE AND TIME : 2005-01-23 17:01:23
ORDER NUMBER : 200501231754Q2048571414
PAYPAL ORDER NUM. :S-3BA091029W816301D
ORDER TYPE : New Order
IP RECORD : 68.7.13.196
YOUR COUNTRY : USA
REFERRER : Ozzu

NAME AND SURNAME : Valeo Corporation
E-MAIL ADDRESS : lisa@ghostbk.org
DOMAIN NAME : beyeu.us

CONTROL PANEL : Ensim Pro
WEBSPACE : 1000 Mb
BANDWIDTH : 10000 Mb
WEBSPACE PRICE PER Mb : 0.002 USD
BANDWIDTH PRICE PER Mb : 0.0005 USD
2 DEDICATED IPs: 36 USD (Yearly)

TOTAL : 94.8 USD
PAYMENT : Yearly
PAYMENT METHOD : PayPal

COMMENTS : Please send me full feature of my order package!
TERMS : Accepted

We do not need your comments that only excuse ordinary PayPal users because of those frauds. Every PayPal users is not skilled PC users and wont have to be! what if they do not know a keylogger hijack their login details when they open a pic? HUH Is your grandfather have to be a skillful PC user to order pizza from net with his PayPal account? THIS IS THE FAULTS OF THE RESPONSIBLES! MAYBE PAYPAL.COM , MAYBE MICROSOFT (because of still cant fix their keylogger security holes...) OR WHATEVER RESPONSIBLE BUT THOSE FRAUDELENT PAYMENTS DONE VIA PAYPAL.COM SO IT IS THE RESPONSIBLE! YOU CANT HELP ME OR HELP FOR THE SAFETY OF INTERNET BY CLAIMING ITS THE ORDINARY USERS FAULT! DAMN :angry:

I need the reports of the web hosting services that have those Vietnamese hackers fraudelent payments via PayPal Please!. I am going to do what a human can do to beat them!


Ramazan Dolay
Newista Founder

3rdcoast
01-24-2005, 12:33 AM
dont use paypal?

submenu
01-24-2005, 01:28 AM
I warned people already about the .183 ip: http://www.webhostingtalk.com/showthread.php?s=&threadid=366770

I've added those reports to my database. Thank you :)

Dark_Coder
01-24-2005, 01:58 AM
I will join this campaign, but how?

dolay
01-24-2005, 03:00 AM
Originally posted by Dark_Coder
I will join this campaign, but how?
HOWTO APPLY THIS CAMPAIGN
1- Report your fraud signups with their IPs
2- Report their e-mails (the damn hacker send e-mail from xedapvn@nhakho.info to ask for instant activation , this hacker(s) include a jpeg file into the e-mail which have a keylogger but our webmail is in safe mode and does not displaying any images)
3-Report how they hack! According to my experiences they are using a modified Trojan Horse called FraggleRock.155 whichs hide on a Dc138.zip file This TH is opening a backdoor on your PC(Windows 9x+XP) for full remote access and it never be able to deleted untill you format the PC!

You can apply to this campaign by posting any more useful information/reports ...

TalonKarrde
01-24-2005, 03:07 AM
I'm sure it's possible to remove the trojan without having to reformat.

cywkevin
01-24-2005, 03:19 AM
Yeah but that's kind of a weaksolution. I mean how manyother trojans do you have that you don't know about yet.

jt2377
01-24-2005, 04:11 AM
Originally posted by dolay
Its not that easy! It is not only a PayPal username+pass hijacking! It is exactly not the faults or excuse of PayPal account owners.

Ie. mail: mrphuong_1984@yahoo.com . This is also the PayPal accounts e-mail. Those hackers are creating their own paypal accounts and they are doing it by hacking PayPal!

As you seen Their hackings are absolutely not limited with only those ways mentioned by you!

I offer you to read my thread well and i would be so glad if you can report their fraud signup details (with their IPs if possible). Otherwise if you claim those are only become from the faults of PayPal users then those hackers will continue to make fraud signups forever and we and most of the known web hosting services that work with PayPal will suffer from those frauds forever. Aiming of this thread is for taking the attention of real responsibles

i doubt anyone have break in or hack paypal servers. there are no news reported about paypal server being hacked. like amish_geek say once hackers gain control of user name and password. they can do what they want with it. thus, this is not paypal fault if users did not follow paypal security guideline.

unless you have solid report on paypal/ebay servers got hacked. the phising scam and fraud order are usually paypal/ebay users giving out their user name and password without verified if it is indeed a real paypal email.

dolay
01-24-2005, 05:59 AM
Originally posted by jt2377
i doubt anyone have break in or hack paypal servers. there are no news reported about paypal server being hacked. like amish_geek say once hackers gain control of user name and password. they can do what they want with it. thus, this is not paypal fault if users did not follow paypal security guideline.

unless you have solid report on paypal/ebay servers got hacked. the phising scam and fraud order are usually paypal/ebay users giving out their user name and password without verified if it is indeed a real paypal email.
If you read the thread from begining i think you can not understand what i wrote! This thread is not opened to validate that PayPal server or systems have been hacked...

I offer you also to all WHT members thiking widely, clearly.
There is a transaction system called PayPal. This systems is the most used and famous fund transfer sytem ever on net and they taking the 3-4% of every funds that transferred. And some Vietnameses are hijacking or hacking (please dont get stick with that matter if its hacked or hijacked.... this thread is not opened to discussit) PayPal accounts organizedly and making fraudelent purchases mainly from web hosting services! Becarefull that word organized There is an organized group of Vietnamese for those PayPal hack, hijack, steal or whatever you called. We have an old Turkish tale that said for those kind of situations at Turkiye in (after the Nasreddin Hodja's house ripped-off at night, everyone started to accuse Hodja when they awared robbery in the morning by saying why dont you lock the door twice, why dont you hide your valuable goods, why dont you..... Then Hodja shout that "Damn! Isnt there any guilty of the thief )
Like Hodja said Isnt there any guilty of the thief?
If you dont guilty the thiefs, man! you cant lock all the door. There is not a door that can stand to thiefs.
This thread aim is taking care to those thiefs and must be taken by PayPal

othellotech
01-24-2005, 07:30 AM
simple answer ... dont use paypal ;)

jt2377
01-24-2005, 09:15 AM
Originally posted by dolay
If you read the thread from begining i think you can not understand what i wrote! This thread is not opened to validate that PayPal server or systems have been hacked...

I offer you also to all WHT members thiking widely, clearly.
There is a transaction system called PayPal. This systems is the most used and famous fund transfer sytem ever on net and they taking the 3-4% of every funds that transferred. And some Vietnameses are hijacking or hacking (please dont get stick with that matter if its hacked or hijacked.... this thread is not opened to discussit) PayPal accounts organizedly and making fraudelent purchases mainly from web hosting services! Becarefull that word organized There is an organized group of Vietnamese for those PayPal hack, hijack, steal or whatever you called. We have an old Turkish tale that said for those kind of situations at Turkiye in (after the Nasreddin Hodja's house ripped-off at night, everyone started to accuse Hodja when they awared robbery in the morning by saying why dont you lock the door twice, why dont you hide your valuable goods, why dont you..... Then Hodja shout that "Damn! Isnt there any guilty of the thief )
Like Hodja said Isnt there any guilty of the thief?
If you dont guilty the thiefs, man! you cant lock all the door. There is not a door that can stand to thiefs.
This thread aim is taking care to those thiefs and must be taken by PayPal

lol. i can understand that you're upset about fraud order because people got phised by paypal spoofed email. like i said, it was not hack. they didn't hack into paypal server. you're the one who should read your own thread more carefully because that's what you said several time about how those hacker "hack" (as you call it) to make fraud order (you said they have several way to hack beside spoof email but all along it was only the phising trick)

look, if you're piss off about paypal not able to take care phising problem (not hack problem) and you think paypal didn't do a good job on educate their customers about phising (which paypal did, they work with their FBI and send out newsletter to warm their customers about phising scam, what more do you want paypal do) then just stop using paypal as the payment system for your hosting. there are several other alternative. You don't like the way Microsoft do business or how buggy their software is...Don't use it! No one put a gun on your head and if you don't like PayPal service or you beleive it's all PayPal's fault to process all those fraud order then don't use it. Try other alternative.

being piss off, sound loud, and rude won't get you anywhere. either try other payment process or stop offering paypal payment option.

dolay
01-24-2005, 10:24 AM
Originally posted by jt2377
lol. i can understand that you're upset about fraud order because people got phised by paypal spoofed email. like i said, it was not hack. they didn't hack into paypal server. you're the one who should read your own thread more carefully because that's what you said several time about how those hacker "hack" (as you call it) to make fraud order (you said they have several way to hack beside spoof email but all along it was only the phising trick)

look, if you're piss off about paypal not able to take care phising problem (not hack problem) and you think paypal didn't do a good job on educate their customers about phising (which paypal did, they work with their FBI and send out newsletter to warm their customers about phising scam, what more do you want paypal do) then just stop using paypal as the payment system for your hosting. there are several other alternative. You don't like the way Microsoft do business or how buggy their software is...Don't use it! No one put a gun on your head and if you don't like PayPal service or you beleive it's all PayPal's fault to process all those fraud order then don't use it. Try other alternative.

being piss off, sound loud, and rude won't get you anywhere. either try other payment process or stop offering paypal payment option.

What an idea.... Oh ok. then lets not use internet!
Yes I am so angry but i am not thinking as straight as you.
How do you think to carry 500 PayPal payers of us and to where? And why am i have to kill a business because of some bastards?
When it comes to reading, English is not my mother language, maybe i cant told clearly but you still on sticked on describing if it have to be called hacking or hijacking or stealing or whatever sht...
I do not think you still can understand that but i would like to repeat that for the 4th time. I do not open that thread to describe and put a correct name for those Vietnamese action. I opened that thread for whom abused from those Vietnamese PayPal fraudelent signups. And think if we going to report their IPs and actions maybe PayPal or other responsibles take care of it more strongly....
If you going to continue to discuss what the exact name have to put on those illegal actions or weak ideas about that matter , maybe you would like yo open another thread! Please dont make this thread's aim get out from its road.

aracnet
01-24-2005, 04:02 PM
Ok! Ok!. I think we should turn to main idea of the topic. There are some hackers and they are stealing someone's paypal paswords and usernames or creating theirselfs paypal accounts with stolen credit cards.And we should stop them if we can.We should help each other not to fight.

As i see on the other forums there are many people has problems with vietnamese hackers. So it is so simple to understand that there is a big problem.

By the way it is very "ironic idiotic thing" that some one saying "Do not be a Rude" and swearing people! You should shame on you jt2377 :blush:

jt2377
01-24-2005, 07:24 PM
Originally posted by aracnet
By the way it is very "ironic idiotic thing" that some one saying "Do not be a Rude" and swearing people! You should shame on you jt2377 :blush:

care to explain?